An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possibl
SAP Banking Services (Generic Market Data), versions - 400, 450, 500, allows an unauthorized user to display protected B
SAP ERP (HCM Travel Management), versions - 600, 602, 603, 604, 605, 606, 607, 608, allows an authenticated but unauthor
AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php
SAP Solution Manager 7.2 (User Experience Monitoring), version - 7.2, does not perform necessary authorization checks fo
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, w
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security chec
In WifiNetworkSuggestionsManager of WifiNetworkSuggestionsManager.java, there is a possible permission revocation due to
In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local e
In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. Th
Privilege escalation by using an altered debug policy image can occur as the XPU protecting the debug policy regions are
In onKeyguardVisibilityChanged of key_store_service.cpp, there is a missing permission check. This could lead to local e
In simulatePackageSuspendBroadcast of NotificationManagerService.java, there is a missing permission check. This could l
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a mi
In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing syst
Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission c
A vulnerability in the Enable Secret feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in
In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. Th
In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local
In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lea
In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local esc
In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalati
In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding aud
In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing permission check. This could lea
In Bluetooth, there is a possible spoofing of bluetooth device metadata due to a missing permission check. This could le
In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. Th
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permiss
BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool i
BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allo
In Saibo Cyber Game Accelerator 3.7.9 there is a local privilege escalation vulnerability. Attackers can use the constru
In DriverGenius 9.61.5480.28 there is a local privilege escalation vulnerability in the driver wizard, attackers can use
In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due t
In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to
In callUnchecked of DocumentsProvider.java, there is a possible permissions bypass due to a missing permission check. Th
In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missi
In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a
In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalat
In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and t
GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.10, allows authenticated users with bas
Opencast before 8.1 and 7.6 allows unauthorized public access to all media and metadata by default via OAI-PMH. OAI-PMH
SAP AS ABAP (SAP Landscape Transformation), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_
An information disclosure issue was discovered GitLab versions < 12.1.2, < 12.0.4, and < 11.11.6 in the security dashboa
In Kronos Web Time and Attendance (webTA) 3.8.x and later 3.x versions before 4.0, the com.threeis.webta.H491delegate se
GitLab EE 8.0 through 12.7.2 has Incorrect Access Control.
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. Several PHP pages, and other type of
SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allo
Frequently Asked Questions
What is CWE-862?
CWE-862 (Missing Authorization) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-862?
There are 10,347 CVE records associated with CWE-862 in our database. Of these, 472 are critical severity, 2109 are high severity, and 6422 are medium severity.
How can I protect against CWE-862 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-862 using AI-powered security agents.
Detect CWE-862 Vulnerabilities
CyberStrike's AI agents automatically detect missing authorization vulnerabilities across your infrastructure.
Get Started